Minacce e avversari · Furto di credenziali
Microsoft ha osservato una campagna che usa colloqui di lavoro finti per veicolare pacchetti NPM malevoli. I pacchetti installano backdoor OtterCookie e FlexibleFerret che esfiltrano API token, credenziali cloud, wallet crypto e codice sorgente.
1 fonte · 11 mar
Microsoft Security Blog
Contagious Interview: Malware delivered through fake developer job interviews | Microsoft Security Blog
Threat actors pose as recruiters from crypto and AI companies and deliver backdoors such as OtterCookie and FlexibleFerret through fake coding assessments.
originalePart of the PlainSec briefing for 2026-03-12
Every edition of this story: Colloqui Tecnici Falsi Installano Backdoor e Rubano Credenziali